IT & Cyber Audit
Third-Party SOC Assurance
Outsourcing moves the controls, not the accountability; ISAE 3402 / SOC reports are how you obtain assurance over them.
Why outsourced controls still belong on the audit file
When financial or HR processing is outsourced to a service provider or cloud host, the controls move but the accountability does not โ the accounting officer remains responsible, and the auditor must obtain assurance over the provider's control environment. An ISAE 3402 or SOC report is the standard mechanism for that assurance, and a missing or expired report leaves a control gap the AGSA cannot bridge. AuditPro Core tracks the coverage and currency of assurance reports across the entity's outsourced providers and identifies the complementary user-entity controls the entity itself must operate.
The Numbers
AuditPro Core renders this view from your tenant's live, tamper-evident records. The figures below are illustrative sample data.
Critical providers
38
Current SOC report
26
of 38
Qualified opinions
3
CUECs unactioned
19
Providers by assurance status
Providers needing attention
| Provider | Service | Status |
|---|---|---|
| Cloud host A | Hosting | Expired |
| Payroll bureau | Payroll run | Qualified |
| Print vendor | Billing print | No report |
Figures shown are illustrative sample data for demonstration. AuditPro Core renders these views from your own tenant's live, tamper-evident records.
Type 1 versus Type 2 reports
A Type 1 report opines on control design at a point in time; a Type 2 also tests operating effectiveness over a period. Only a Type 2 supports reliance for a financial-statement audit.
Currency and period coverage
A report must cover the entity's financial year. An expired report, or a gap period not covered, leaves part of the year without assurance and may require a bridging letter.
Complementary user-entity controls
Every SOC report lists controls the provider assumes the user entity operates. If those are ignored, the provider's clean opinion does not protect the entity at all.
Sub-service organisations
Providers often rely on further sub-providers โ a cloud host beneath a SaaS vendor. The assurance chain must be followed through, or whole layers of the stack go unexamined.
How AuditPro Core Bridges the Gap
- Report inventory: each outsourced provider is tracked with its report type, period covered and expiry.
- Currency alerts: reports that have expired or fail to cover the financial year are flagged before the audit relies on them.
- CUEC tracking: complementary user-entity controls are captured and assigned so the entity actually operates its side of the arrangement.
- Audit-ready export: the assurance position across all providers exports as a single schedule for the audit file.
Key Takeaways
- Only a Type 2 report supports reliance for a financial-statement audit.
- The report must cover the financial year โ watch for gap periods and expiry.
- Complementary user-entity controls must be operated, or the clean opinion is worthless to you.
- Follow the chain to sub-service organisations so no layer goes unexamined.
See This on Your Own Data
AuditPro Core renders this dashboard from your tenant's live, tamper-evident records โ every figure traceable to source.
